v1.1.1
·
5 commits
to main
since this release
Highlights
- Sandbox mounts are the file-tool boundary: host file tools (
read,edit,write,patch) are fenced to the sandbox mounts, and theexternal_directorypermission rules are dropped from the loop and audit rulesets. A single boundary now governs both in-container and host file access.
What's Changed
- refactor(sandbox): make sandbox mounts the file-tool boundary (#103)